QID 377910

Date Published: 2023-01-18

QID 377910: Oracle MySQL Connectors 8.0.x Denial of Service (DoS) Vulnerability (CPUJAN2023)

MySQL Connectors provide connectivity to the MySQL server for client programs.

Affected Version:
MySQL Connector/ODBC 8.0.31 and prior
MySQL Connector/C++ 8.0.31 and prior
MySQL Connector/Net 8.0.31 and prior
MySQL Connector/Python 8.0.31 and prior
QID Detection Logic (Authenticated):
This QID checks for the file version of MySQL Connector

Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    MySQL has released Oracle MySQL Connector 8.0.32 to mitigate these vulnerabilities. Refer to advisory MySQL Connector 8.0.x

    Vendor References

    CVEs related to QID 377910

    Software Advisories
    Advisory ID Software Component Link
    MySQL Connector 8.0.x URL Logo www.oracle.com/security-alerts/cpujan2023.html#AppendixMSQL